A flexible authorization mechanism for relational data management systems

Citation
E. Bertino et al., A flexible authorization mechanism for relational data management systems, ACM T INF S, 17(2), 1999, pp. 101-140
Citations number
21
Categorie Soggetti
Information Tecnology & Communication Systems
Journal title
ACM TRANSACTIONS ON INFORMATION SYSTEMS
ISSN journal
10468188 → ACNP
Volume
17
Issue
2
Year of publication
1999
Pages
101 - 140
Database
ISI
SICI code
1046-8188(199904)17:2<101:AFAMFR>2.0.ZU;2-1
Abstract
In this article, we present an authorization model that can be used to expr ess a number of discretionary access control policies for relational data m anagement systems. The model permits both positive and negative authorizati ons and supports exceptions at the same time. The model is flexible in that the users can specify, for each authorization they grant, whether the auth orization can allow for exceptions or whether it must be strongly obeyed. I t provides authorization management for groups with exceptions at any level of the group hierarchy, and temporary suspension of authorizations. The mo del supports ownership together with decentralized administration of author izations. Administrative privileges can also be restricted so that owners r etain control over their tables.